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Cloud Platform Environment 
Security at scale on hybrid clouds 


15+ products providing 
comprehensive suite of security gj 
solutions | 


10,300+ customers i i 


7 shared cloud platforms across © 
North America, Europe & Asia 


70+ private clouds platforms 
deployed globally... on-prem, AWS, C» 
Azure, GCP 


© Qualys 


Gloud Platform Highlights 


1* trillion security events 
annually 


3+ billion scans annually E [= 


2.5+ billion messages daily E Ri 
across Kafka clusters © 


620+ billion data points indexed 
in our Elasticsearch clusters a i^ 


a 
Unprecedented 2-second visibility C» 
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Oualys Gloud Platform 


Sensors, Data Platform, Microservices, DevOps 
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Cloud Passive Scanners Scanners Appliances Virtual Scanners Internet Scanners 


Agents © Qualys 


Oualys Sensor Platform 


Scalable, self-updating 8 centrally managed 


Physical 


Legacy data centers 
Corporate infrastructure 


Continuous security and 
compliance scanning 


© 


Virtual 


Private cloud 
infrastructure 


Virtualized Infrastructure 


Continuous security and 
compliance scanning 


© 


Cloud/Container 
Commercial laaS & PaaS 
clouds 


Pre-certified in market 
place 


Fully automated with 
API orchestration 


Continuous security and 
compliance scanning 


© 


Cloud Agents 
Light weight, multi- 
platform 


On premise, elastic 
cloud & endpoints 


Real-time data collection 


Continuous evaluation 
on platform for security 
and compliance 


Passive 


Passively sniff on 
network 


Real-time device 
discovery & 
identification 


Identification of APT 
network traffic 


Extract malware files 
from network for 
analysis 


[e] 


API 


Integration with Threat 
Intel feeds 


CMDB Integration 


Log connectors 
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Sensor Platform - Cloud Agents 


Cloud connected, centrally managed, 
always up-to-date 


Supports on-premises servers, public 
clouds, user endpoints 


Consolidate multiple security 
solutions with one agent 


Activate new Qualys apps without 
requiring reinstall or reboot 


Lightweight - 3MB 


Number of Cloud Agents Sold 


— + 


LTM 
24 2017 


LTM 
Q1 2018 


LTM 
Q2 2018 
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LTM 
Q3 2018 
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Data Platform-as-a-Service 


Right database for the right use 
case 


* Highly scalable architecture 

* Predictable performance at scale 
* Distributed and fault-tolerant 

* Multi-datacenter support 

e Open-source 

* Commodity hardware 
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Data Platform-as-a-Service 


Asynchronous, 
event-driven 
architecture 


Foundation for 
Qualys Cloud 
Platform 


Over 2.5 billion 
messages per day 


4 elastic 
Elasticsearch 


Search for anything 


Over 620 billion 
data points indexed 


Estimating about | 
trilllon data points 
beyear end 


SIE Cassandra 


Cassandra 


Low latency 
storage 


Source of truth for 
data across 
multiple products 


e redis 


Redis 
In-memory cache 


Improved system 
performance for 
frequently 
accessed data 
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Ceph 
Object storage 


Moving Oracle and 
in-house blob 
storage into Ceph 
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Microservices & Cloud Native Architectures 
Reduce risk and ship faster 


Change how we design and build 
applications and services 
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e Monoliths to microservices i Vault Ç Consul 
* Well defined APIs T 
* Packaged in containers A service d A serice |. 


e Deployed on elastic infrastructure 
e 12-Factor apps 
* CI/CD, Service Registry, Config Servers 


kubernetes 
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DevOps - Increased Efficiency 


Goal is to make software 
delivery vastly more efficient 


Supporting about 80 shared 
and private cloud 
deployments. 


Google Cloud Platforn 


seer amazon 
ks webservices 


à 0 IBM Cloud 
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Automation - Infrastructure as Code 


Treat systems running your 


software as If they themselves 
eii. kubernetes 
are software ES” 


Automate “sf Terraform = ANSIBLE 

* Infra provisioning u M 

* Configuration management W Vault C Consul 
Deployments... @ Jenkins 


Sasing code 
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Monitoring Systems - Observability 


Centrally monitor across all 


platforms using a single-pane M Prometheus IS Grafana 
view E | &> elasticsearch gg logstash jp, kibana 
End-to-end monitoring using 
* Time series metrics 
* Distributed tracing 
* | og aggregation & analytics 


* Alerting 
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pagerduty = catchpoint- 


© Qualys 


Integrated Security - DevSecOps 


Built-in security practices 
across the DevOps 

lifecycle 

Qualys-on-Qualys 

e Manage vulnerabilities 

* Comply with policies 

e Secure and shield web apps 
e Validate file integrity 

* Monitor systems 


Vulnerability Alerts 
Guidence& 


Centraized 
Visibility & Control 


Attack Protection& 
Threat Intelligence 
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Oualys Gloud Platform 


Eee C 
of Applications 


E Authentication Authorization Subscription Indexing Data Sync Tagging 
Shared Services Service Service Service Service Service Service 
Messaging, Data 99 k E 9 A i 
ging, Data, afka EE z 6% redis i 
Analytics Platform E @ ceph o: elastic cassandra Flink 
Infrastructure and Logging Monitoring Config Mgmt. siia CI/CD E. 
DevOps Toolchain Y 
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Oualys Gloud Applications 


Asset Inventory CMDB Sync Cloud Inventory 
M 


Certificate Inventory 


aintain full, instant visibility of all your Synchronize asset information from Inventory of all your cloud assets across Inventory of TLS/SSL digital certificates on 

global IT assets Oualys into ServiceNow CMDB AWS, Azure, GCP and others a global scale 

Vulnerability Management Threat Protection Continuous Monitoring (toc) Indication of Compromise 
Continuously detect and protect against Pinpoint your most critical threats Alerts you in real time about network Continuously monitor endpoints to detect 
attacks, anytime, anywhere and prioritize patching irregularities suspicious activity 

Container Security cra) Certificate Assessment Patch Management (Beta) 

Discover, track, and continuously protect Assess all your digital certificates for TLS/ Select, manage, and deploy patches to 
containers i SSL vulnerabilities remediate vulnerabilities 

| COMPLIANCE MONITORING | MONITORING 

Policy Compliance PCI Compliance File Integrity Monitoring Security Configuration 
Assess security configurations of IT Automate, simplify and attain PCI Log and track file changes across global IT Assessment ration assessment of 
systems throughout your network compliance guickly systems global IT assets 

Cloud Security Assessment Security Assessment Guestionnaire 
Get full visibility and control across Minimize the risk of doing business with 
all public cloud instances vendors and other third parties 

| WEB APPLICATION SECURITY| APPLICATION SECURITY 

Web Application Scanning Web Application Firewall 
Secure web applications with end-to-end Block attacks and virtually patch web 
protection application vulnerabilities 
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Advanced Gorrelation 4 Analytics 


ML/AI Service Orchestration & Automation UEBA 
Patterns | Outlier | Predictive SoC Integration | Playbooks | Response User & Entity Behavior Analytics 
Threat Hunting Security Analytics Advanced Correlation 
Search | Exploration | Behavior Graph Anomaly | Visualization | Dashboard Actionable Insights | Out-of-box Rules 


Qualys Security Data Lake Platform 


Data Ingestion | Normalization | Enrichment | Governance 
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Network Security Server End Point Qualys Apps Apps Cloud Users loT 


Qualys Quick Connectors 
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Thank You 


Dilip Bachwani 
dbachwanimogualys.com 


